# Proper way to create new event from Logstash Ruby filter

**URL:** <https://discuss.elastic.co/t/proper-way-to-create-new-event-from-logstash-ruby-filter/232119>\
**Category:** Logstash\
**Created:** [May 11, 2020, 11:44pm UTC](https://discuss.elastic.co/t/proper-way-to-create-new-event-from-logstash-ruby-filter/232119 "2020-05-11T23:44:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![szgeri](https://avatars.discourse-cdn.com/v4/letter/s/4bbf92/32.png) [@szgeri](https://discuss.elastic.co/u/szgeri)\
**Post date:** [May 11, 2020, 11:44pm UTC](https://discuss.elastic.co/t/proper-way-to-create-new-event-from-logstash-ruby-filter/232119/1 "2020-05-11T23:44:25Z")

</div>

Hi,

I would like to somehow create new event with Logstash Ruby filter but actually with no success. I tried a lot of versions and syntaxes, searched for many online topics and documentations and the result is the same.  
For example one code snippet for this purpose:

```auto
new_custom_event = LogStash::Event.new()
new_custom_event.set("cpu_test_load", 34)
new_event_block.call(new_custom_event)

```

I did not get any errors with this one, finally syslog shows the new event with "cpu\_test\_load", "@timestamp" and "@version" fields but Kibana does not show it within the destination index pattern. What do I wrong? Could anybody help with this problem?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 12, 2020, 12:00am UTC](https://discuss.elastic.co/t/proper-way-to-create-new-event-from-logstash-ruby-filter/232119/2 "2020-05-12T00:00:38Z")

</div>

I have never had any success creating new events with the code option of a ruby filter. All the posts that explain how to do it appear to discuss techniques that are no longer valid.

However, you can definitely create new events if you use the [path](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html#_using_a_ruby_script_file) option to a ruby filter, since that has to return an array of events.

---

<div class="post-metadata">

**Author:** ![szgeri](https://avatars.discourse-cdn.com/v4/letter/s/4bbf92/32.png) [@szgeri](https://discuss.elastic.co/u/szgeri)\
**Post date:** [May 12, 2020, 12:09am UTC](https://discuss.elastic.co/t/proper-way-to-create-new-event-from-logstash-ruby-filter/232119/3 "2020-05-12T00:09:58Z")

</div>

Thank you. Maybe i will try it but my opinion is that it should work this way as well. Syslog shows the created new event with minimal field list, it seems that only Kibana drops it. Why? 😃 I think there is only one small setting related or any other problem which cause the situation.

---

<div class="post-metadata">

**Author:** ![szgeri](https://avatars.discourse-cdn.com/v4/letter/s/4bbf92/32.png) [@szgeri](https://discuss.elastic.co/u/szgeri)\
**Post date:** [May 12, 2020, 8:10am UTC](https://discuss.elastic.co/t/proper-way-to-create-new-event-from-logstash-ruby-filter/232119/4 "2020-05-12T08:10:55Z")

</div>

I found an alternative solution. 🙂

First, it is necessary to build such structure (array of hashes via Ruby filter) from what we want to create new events - for each hash object it is important to place an index value, otherwise we will get Elasticsearch indexing errors after Logstash restart. When the structure is completed, this array should be inserted into existing event via `event.set`. That's all for Ruby filter.  
After then we need to apply `split` filter on existing event and within `field` attribute, define previous array of hash objects. Logstash will make as many events as array elements has.

Hope, it will useful for others as well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2020, 8:10am UTC](https://discuss.elastic.co/t/proper-way-to-create-new-event-from-logstash-ruby-filter/232119/5 "2020-06-09T08:10:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
